CVE-2026-18751
Received Received - Intake

External Control of File Name in Citrix WorkSpace App for MacOS

Vulnerability report for CVE-2026-18751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Citrix Systems, Inc.

Description

External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
citrix workspace_app 2607

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an external control of file name or path issue in Citrix WorkSpace App for MacOS. It allows a local authenticated user to escalate privileges to root by modifying arbitrary root files due to improper handling of file paths.

Detection Guidance

This vulnerability requires local authenticated access and affects Citrix Workspace App for Mac before version 2607. Detection involves checking the installed version of the app. Use the command 'defaults read /Library/Preferences/com.citrix.receiver.plist CFBundleShortVersionString' in Terminal to verify the version. If the version is below 2607, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to gain root privileges on your device. This could lead to full system compromise, unauthorized data access, or installation of malicious software.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations must mitigate this risk to maintain compliance.

Mitigation Strategies

Update Citrix Workspace App for Mac to version 2607 or later immediately to mitigate the risk of privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart